mirror of
https://gitea.osmocom.org/sim-card/pysim.git
synced 2026-05-03 06:58:53 +03:00
PyYAML versions 5.1–5.3.1 are vulnerable to CVE-2020-1747, which allows arbitrary code execution through yaml.FullLoader. While PyYAML 5.4+ patches this, the dependency specification (pyyaml >= 5.1) doesn't guarantee a safe version. Let's increase the requirement to version 5.4 to ensure a safe version of is used. This patch is based on suggestions from: "YanTong C <chyeyantong03@gmail.com>" Change-Id: I901c76c59e9c1bab030eab81038e04a475b32510
19 lines
317 B
Plaintext
19 lines
317 B
Plaintext
pyscard
|
|
pyserial
|
|
pytlv
|
|
cmd2>=2.6.2,<3.0
|
|
jsonpath-ng
|
|
construct>=2.10.70
|
|
bidict
|
|
pyosmocom>=0.0.12
|
|
pyyaml>=5.4
|
|
termcolor
|
|
colorlog
|
|
pycryptodomex
|
|
cryptography
|
|
git+https://github.com/osmocom/asn1tools
|
|
packaging
|
|
git+https://github.com/hologram-io/smpp.pdu
|
|
smpp.twisted3 @ git+https://github.com/jookies/smpp.twisted
|
|
smpplib
|